Skip to main content
Cybersecurity

Microsoft 365 Copilot Security: Fix Oversharing First

Microsoft 365 Copilot Security: Fix Oversharing First

Here’s the short version: Microsoft 365 Copilot security is mostly a permissions problem. Copilot answers from files, mail, and sites the signed-in user can already open. If sharing is a mess, Copilot makes that mess searchable in plain English.

This is not a “turn off AI” essay. Copilot is useful when the tenant is honest. It is a leak amplifier when Anyone-links, leftover guests, and inherited SharePoint permissions are how people actually work. Microsoft’s own privacy documentation is clear that Copilot grounds answers in content the user is allowed to access (Microsoft 365 Copilot privacy). That sentence is the whole security model. The rest of this page is how to make it true in a small or mid-size tenant.

If you want the broader lock-down list, start with the Microsoft 365 security checklist. This post is only Copilot: what it can see, what it cannot, and the order to roll it out without surprising the managing partner.

What Copilot can actually see

Copilot is not browsing the open internet for your matter files. In Microsoft 365 it sits on the Graph: mail, files, meetings, and chats the user already has rights to. Microsoft describes that path in the Copilot architecture overview. Architecture slides are not a control. Permissions are.

In practice that means:

  • A file in a SharePoint library the user can open can be summarized.
  • A OneDrive item shared with “anyone in the organization” can show up for people who never knew the folder existed.
  • A Teams channel with five years of “temporary” guest access is a transcript Copilot can draw from.
  • A mailbox the user can read is in scope for that user, including shared mailboxes they were added to in 2019 and never removed from.

It also means Copilot will not magically open a site that Entra and SharePoint already deny. If the deny is real, the answer is empty. If the deny is theater, Copilot is the person who reads the script out loud.

Licensing still matters. Microsoft lists Copilot requirements so you do not invent a SKU. Requirements are not a security review. You can meet every license checkbox and still have a tenant where “Confidential” is a folder name, not a permission.

Oversharing is the real Copilot risk

The scary story people tell is that the model trains on your data and publishes it. The boring story, which is the one that actually happens, is that Copilot finds the HR spreadsheet that was shared with the whole company in 2021.

Typical oversharing that Copilot will happily use:

PatternWhat Copilot does with it
Anyone linksMicrosoft documents that an unredeemed Anyone-link is not Copilot-searchable. Once someone opens the file, that person’s access is real. Forwarding still spreads it.
“Everyone except external” on a finance libraryThe whole tenant can query it
Broken inheritance on one folderOne “temporary” exception becomes a permanent answer
Guest accounts that never expiredA former vendor’s access becomes a prompt
Public TeamsChannel history is in the graph for members

We cleaned a version of this without Copilot in SharePoint oversharing cleanup for a media agency. Copilot does not create that mess. It removes the friction that used to hide it.

Microsoft’s shareable links page is the product fact for Anyone-links: they skip sign-in and they are not an audit trail. Kill them for client work anyway. Copilot is not the only reason.

Professional reviewing files on a tablet beside a laptop in an office
Copilot can summarize any file the signed-in user can already open

Identity still comes first

Do not buy Copilot seats for people who can still sign in with a password only. Account takeover plus Copilot is a very efficient way to read a tenant. Enforce MFA, kill legacy authentication, and treat Global Admin as a rare tool. That work is in the security checklist and in multi-factor authentication. Copilot does not replace it.

If you have already been through a Conditional Access rollout, you are in better shape than a tenant that licensed Copilot on Security Defaults and hope. Chat interfaces did not repeal identity.

Sensitivity labels and DLP

Permissions decide who can open a file. Labels and DLP decide how that file behaves when someone tries to email it, copy it, or ask Copilot about it in a way you have banned.

Microsoft documents sensitivity labels as the way to classify content and apply protection. For a 25-person firm, you do not need a 12-label taxonomy. You need a few labels people will actually use: Public, Internal, Confidential, and maybe Restricted for legal or clinical material.

Data loss prevention is the net under that. DLP will not fix Anyone-links by itself. It will catch some of the “email this client list to a personal Gmail” class of mistake, which Copilot can otherwise help someone do faster.

If you handle ePHI, labels are not a HIPAA certification. They are how you keep Copilot from becoming a shortcut through a clinic library that was never meant for the whole staff. Pair this with the HIPAA compliance checklist and a real compliance engagement if you need a dated analysis.

A board-level AI risk write-up is useful language. It is not a Copilot setting. Do not tape a framework PDF to the tenant and call it a control. Sharing defaults, labels, and RCD are the controls.

Restricted Content Discovery

Do not plan a new Copilot rollout on Restricted SharePoint Search. Microsoft’s RSS page says the feature is retiring and that new enablement has been blocked since 31 July 2026. If you already had it on, treat it as a clock, not a strategy.

The current staging control is Restricted Content Discovery: a per-site flag that keeps that site out of organization-wide search and Copilot while you review permissions. It does not change who can open the site if they already have a link. It is a hide-from-discovery control, not a new permission model.

Use it as a gate:

  1. Inventory sites that hold finance, HR, legal, or clinical files.
  2. Turn RCD on for the messy ones before Copilot seats go live.
  3. Review members, Anyone-links, and “everyone except external.”
  4. Turn RCD off only when the site is honest, not because Copilot “felt limited.”

RCD is not a substitute for killing Anyone-links. It is how you roll Copilot out without indexing the junk drawer on day one. SharePoint Advanced Management and Purview exist for larger tenants. A 25-person firm can still do site-by-site RCD plus a sharing default.

What Copilot is not

Write these on the statement of work if you are rolling this out with us, and on the internal FAQ if you are doing it yourself.

  • Not a new security boundary. If a user can open it, Copilot can talk about it.
  • Not a backup. Summaries are not restores. You still need Microsoft 365 backup.
  • Not a DLP product by itself. Labels and DLP are separate work.
  • Not a reason to skip MFA. Stolen sessions still get Copilot.
  • Not an excuse to skip vendor review. Plugins and connectors are vendor risk.

Conference table with laptops after a working session
Review sharing and site access before Copilot seats go live

A practical Copilot rollout order

Week 1: stop the obvious leaks

Turn off organization-wide Anyone-links you do not need. Expire guest access that has no owner. List the SharePoint sites that hold finance, HR, legal, or clinical files. Do not license Copilot yet.

Week 2: hide the messy sites

Turn on Restricted Content Discovery for finance, HR, legal, and clinical sites you have not reviewed. Confirm a test user in sales cannot get Copilot to summarize a finance library they should never have seen. If they still can, that user already has permission. Fix the permission, not the chat box.

Week 3: labels for the libraries that matter

Apply Confidential or Restricted to the sites from week 1. Keep the label count small. Train two people who actually upload files, not a 40-slide deck.

After that: seats, then watch

License Copilot for a pilot group that already uses Microsoft 365 well. Watch sharing reports and Copilot usage. Expand when the test user still cannot see the wrong library.

This is cybersecurity and tenant hygiene, not a Copilot sales motion. If the tenant is a wreck, fix sharing first. Copilot can wait a month. A leak cannot.

How to check your tenant this week

You do not need a 90-day program to learn whether you are ready.

  1. Sign in as a typical user, not Global Admin.
  2. Ask Copilot to summarize a file from a library they should not belong to. If it can, you have an access problem, not an AI problem.
  3. Search the tenant for “salary,” “wire,” “password,” or your matter naming convention. Note who can see the hits.
  4. List guests older than 90 days. Disable the ones with no owner.
  5. Confirm MFA is enforced, not merely licensed.

If step 2 succeeds, do not buy more Copilot seats. Buy a sharing cleanup.

Also check the admin path. Global Admins see more than a typical user. Testing Copilot only as an admin is how firms declare the tenant “fine” and then a salesperson summarizes the partner compensation file. Use a real role: intake, billing, a first-year associate, a front-desk account.

Watch the sharing reports for a week after the pilot. New Anyone-links and “anyone in the organization” grants are the leading indicator. Copilot usage reports tell you who is asking. Sharing reports tell you whether those questions can reach the wrong library.

If you already have cybersecurity monitoring, treat a Copilot-visible overshare like any other data-exposure finding: owner, due date, proof it is closed. Do not create a separate “AI committee” that never touches SharePoint.

Treat Copilot like a very fast paralegal with the same permissions as the person typing. You would not hand a new hire the entire file room on day one. Do not hand it to a chat box either.

Law firms and clinics feel this first because the file room is the product. A matter folder shared “with the firm” is a Copilot answer waiting for the wrong prompt. The cleanup is still SharePoint and Entra, not a Copilot policy that pretends permissions do not exist.

If you want that review done as a project, contact Secure Techies. We work from Canoga Park. We will tell you whether Copilot is safe to license, or whether the next job is still Anyone-links and leftover guests.

Frequently Asked Questions

Microsoft documents that Microsoft 365 Copilot uses your tenant content to generate answers for users who already have permission to that content. It is not a public internet model you feed your files into for training. The practical risk is still oversharing: if a user can open a file, Copilot can summarize it for them.
Oversharing. Copilot does not create a new back door so much as it makes existing SharePoint, OneDrive, Teams, and mailbox access painfully easy to query. Anyone-links, inherited permissions, and leftover guest access become a chat answer instead of a buried folder.
Labels are not a legal Copilot prerequisite, but they are how you tell the tenant which libraries are confidential. Pair labels with DLP and a sharing cleanup. Turning Copilot on first and labeling later is how finance files show up in a helpful summary for the wrong person.
Restricted Content Discovery is a per-site SharePoint setting that keeps that site out of organization-wide search and Copilot while you review permissions. Microsoft documents it as the current control. Restricted SharePoint Search, the old tenant-wide allow list, is retiring: new enablement has been blocked since 31 July 2026. RCD is a staging control, not a substitute for fixing sharing.
Yes, if identity, sharing, and recovery are already in decent shape. Enforce MFA, kill Anyone-links you do not need, review guest access, and test that Copilot cannot see sites it should not. Licensing Copilot on a messy tenant is a search engine for your worst folder.
Share

Talk to a real IT expert — free

No sales pressure, no jargon. Just a straight assessment of where your IT and security stand, and what to do next.